Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “reverse engineering”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Memory forensic analysis of a programmable logic controller in industrial control systems

In industrial control systems (ICS), programmable logic controllers (PLCs) are used to automate physical processes such as nuclear plants and power grid stations, and are often subject to cyber attacks. As in conventional IT domain, the memory analysis of the PLCs can help answer important forensic questions about the attack, such as the presence of malicious firmware, injection of modified control logic (the program running on the PLC), and manipulation of I/O devices (e.g., sensors and actuators). Unlike conventional IT domain, PLCs have heterogeneous hardware architecture, proprietary firmware and control software, making it challenging to employ a unified framework for their memory forensics. For merely extracting artifacts of forensic importance, reverse-engineering the firmware is a tedious task, and the effort needs to be repeated for every PLC model. As a community, a step-wise approach to tackle this challenge is to analyze the memory of specific PLCs, and subsequently find a generic framework applicable to all PLCs. Our work is a step forward in this direction. By following a methodology that focuses on the functional layer of PLCs instead of reverse engineering the firmware, we analyze the digital forensic artifacts available in a common PLC, Allen-Bradley ControlLogix 1756-L61. Before diving into the memory dump, we analyze the PLC control software to create a list of important artifacts that are sure to exist in the PLC memory dump. The approach employs a setup where PLC control software RSLogix-5000 is connected to the PLC, and the memory dump can be obtained as and when needed. We create test cases that sequentially highlight each category of artifacts, followed by an examination of the resultant impact on memory. After attaining the listed artifacts, we employ conventional string and known data searches to extract interesting information present in this PLC's memory. The memory analysis profile, presented as a Python library and shared with the community, can help a forensic investigator to readily extract forensic artifacts from the same model's controller. The adopted approach may help researchers in creating memory profile of other PLCs, and ultimately formulating a generic PLC memory analysis framework.

Rais, Muhammad Haris↗

Rapid Prototyping Integrated With Nondestructive Evaluation and Finite Element Analysis

Most reverse engineering approaches involve imaging or digitizing an object then creating a computerized reconstruction that can be integrated, in three dimensions, into a particular design environment. Rapid prototyping (RP) refers to the practical ability to build high-quality physical prototypes directly from computer aided design (CAD) files. Using rapid prototyping, full-scale models or patterns can be built using a variety of materials in a fraction of the time required by more traditional prototyping techniques (refs. 1 and 2). Many software packages have been developed and are being designed to tackle the reverse engineering and rapid prototyping issues just mentioned. For example, image processing and three-dimensional reconstruction visualization software such as Velocity2 (ref. 3) are being used to carry out the construction process of three-dimensional volume models and the subsequent generation of a stereolithography file that is suitable for CAD applications. Producing three-dimensional models of objects from computed tomography (CT) scans is becoming a valuable nondestructive evaluation methodology (ref. 4). Real components can be rendered and subjected to temperature and stress tests using structural engineering software codes. For this to be achieved, accurate high-resolution images have to be obtained via CT scans and then processed, converted into a traditional file format, and translated into finite element models. Prototyping a three-dimensional volume of a composite structure by reading in a series of two-dimensional images generated via CT and by using and integrating commercial software (e.g. Velocity2, MSC/PATRAN (ref. 5), and Hypermesh (ref. 6)) is being applied successfully at the NASA Glenn Research Center. The building process from structural modeling to the analysis level is outlined in reference 7. Subsequently, a stress analysis of a composite cooling panel under combined thermomechanical loading conditions was performed to validate this process.

Abdul-Aziz, Ali↗

RAMSeS: Rapid Analysis of Mission Software Systems

Over the past few decades, software has become ubiquitous as it has been integrated into nearly every aspect of society, including household appliances, consumer electronics, industrial control systems, public utilities, government operations, and military systems. Consequently, many critical national security questions can no longer be answered convincingly without understanding software, including its purpose, its capabilities, its flaws, its communication, or how it processes and stores data. As software continues to become larger, more complex, and more widespread, our ability to answer important mission questions and reason about software in a timely way is falling behind. Today, to achieve such understanding of third-party software, we rely predominantly on the ability of reverse engineering experts to manually answer each particular mission question for every software system of interest. This approach often requires heroic human effort that nevertheless fails to meet current mission needs and will never scale to meet future needs. The result is an emerging crisis: a massive and expanding gap between the national security need to answer mission questions about software and our ability to do so. Sandia National Laboratories has established the Rapid Analysis of Mission Software Systems (RAMSeS) effort, a collaborative long-term effort aimed at dramatically improving our nation’s ability to answer mission questions about third-party software by growing an ecosystem of tools that augment the human reverse engineer through automation, interoperability, and reuse. Focusing on static analysis of binary programs, we are attempting to identify reusable software analysis components that advance our ability to reason about software, to automate useful aspects of the software analysis process, and to integrate new methodologies and capabilities into a working ecosystem of tools and experts. We aim to integrate existing tools where possible, adapt tools when modest modifications will enable them to interoperate, and implement missing capability when necessary. Although we do hope to automate a growing set of analysis tasks, we will approach this goal incrementally by assisting the human in an ever-widening range of tasks.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

External Dependencies-Driven Architecture Discovery and Analysis of Implemented Systems

A method for architecture discovery and analysis of implemented systems (AIS) is disclosed. The premise of the method is that architecture decisions are inspired and influenced by the external entities that the software system makes use of. Examples of such external entities are COTS components, frameworks, and ultimately even the programming language itself and its libraries. Traces of these architecture decisions can thus be found in the implemented software and is manifested in the way software systems use such external entities. While this fact is often ignored in contemporary reverse engineering methods, the AIS method actively leverages and makes use of the dependencies to external entities as a starting point for the architecture discovery. The AIS method is demonstrated using the NASA's Space Network Access System (SNAS). The results show that, with abundant evidence, the method offers reusable and repeatable guidelines for discovering the architecture and locating potential risks (e.g. low testability, decreased performance) that are hidden deep in the implementation. The analysis is conducted by using external dependencies to identify, classify and review a minimal set of key source code files. Given the benefits of analyzing external dependencies as a way to discover architectures, it is argued that external dependencies deserve to be treated as first-class citizens during reverse engineering. The current structure of a knowledge base of external entities and analysis questions with strategies for getting answers is also discussed.

Ganesan, Dharmalingam↗

Transition metal vacancy and position engineering enables reversible anionic redox reaction for sodium storage

Triggering the anionic redox reaction is an effective approach to boost the capacity of layered transition metal (TM) oxides. However, the irreversible oxygen release and structural deterioration at high voltage remain conundrums. Herein, a strategy for Mg ion and vacancy dual doping with partial TM ions pinned in the Na layers is developed to improve both the reversibility of anionic redox reaction and structural stability of layered oxides. Both the Mg ions and vacancies (□) are contained in the TM layers, while partial Mn ions (~1.1%) occupy the Na-sites. The introduced Mg ions combined with vacancies not only create abundant nonbonding O 2p orbitals in favor of high oxygen redox capacity, but also suppress the voltage decay originated from Na–O–□ configuration. The Mn ions pinned in the Na layers act as “rivets” to restrain the slab gliding at extreme de-sodiated state and thereby inhibit the generation of cracks. The positive electrode, Na 0.67 Mn 0.011 [Mg 0.1 □ 0.07 Mn 0.83 ]O 2 , delivers an enhanced discharge capacity and decent cyclability. This study provides insights into the construction of stable layered oxide positive electrode with highly reversible anionic redox reaction for sodium storage.

Cai, Congcong [Wuhan Univ. of Technology (China)]↗

An empirical investigation of organic software product lines

Abstract Software product line engineering is a best practice for managing reuse in families of software systems that is increasingly being applied to novel and emerging domains. In this work we investigate the use of software product line engineering in one of these new domains, synthetic biology. In synthetic biology living organisms are programmed to perform new functions or improve existing functions. These programs are designed and constructed using small building blocks made out of DNA. We conjecture that there are families of products that consist of common and variable DNA parts, and we can leverage product line engineering to help synthetic biologists build, evolve, and reuse DNA parts. In this paper we perform an investigation of domain engineering that leverages an open-source repository of more than 45,000 reusable DNA parts. We show the feasibility of these new types of product line models by identifying features and related artifacts in up to 93.5% of products, and that there is indeed both commonality and variability. We then construct feature models for four commonly engineered functions leading to product lines ranging from 10 to 7.5 × 10 20 products. In a case study we demonstrate how we can use the feature models to help guide new experimentation in aspects of application engineering. Finally, in an empirical study we demonstrate the effectiveness and efficiency of automated reverse engineering on both complete and incomplete sets of products. In the process of these studies, we highlight key challenges and uncovered limitations of existing SPL techniques and tools which provide a roadmap for making SPL engineering applicable to new and emerging domains.

97 MATHEMATICS AND COMPUTING↗

CAN-D: A Modular Four-Step Pipeline for Comprehensively Decoding Controller Area Network Data

Controller area networks (CANs) are a broadcast protocol for real-time communication of critical vehicle subsystems. Original equipment manufacturers of passenger vehicles hold secret their mappings of CAN data to vehicle signals, and these definitions vary according to make, model, and year. Without these mappings, the wealth of real-time vehicle information hidden in the CAN packets is uninterpretable, severely impeding vehicle-related research, including CAN cybersecurity and privacy studies, aftermarket tuning, efficiency and performance monitoring, and fault diagnosis to name a few. Guided by the four-part CAN signal definition, we present CAN-D (CAN-Decoder), a modular, four-step pipeline for identifying each signal's boundaries (start bit and length), endianness (byte ordering), signedness (bit-to-integer encoding), and by leveraging diagnostic standards, augmenting a subset of the extracted signals with meaningful, physical interpretation. En route to CAN-D, we provide a comprehensive review of the CAN signal reverse engineering research. All previous methods ignore endianness and signedness, rendering them incapable of decoding many standard CAN signal definitions. Incorporating endianness grows the search space from 128 to 4.72E21 signal tokenizations and introduces a web of changing dependencies. In response, we formulate, formally analyze, and provide an efficient solution to an optimization problem, allowing identification of the optimal set of signal boundaries and byte orderings. In addition, we provide two novel, state-of-the-art signal boundary classifiers—both of which are superior to previous approaches in precision and recall in three different test scenarios—and the first signedness classification algorithm, which exhibits a $>$ 97% F-score. Altogether, CAN-D is the only solution with the potential to extract any CAN signal that is also the state of the art. In evaluation on 10 vehicles of different makes, CAN-D's average $\ell ^1$ error is five times better (81% less) than all previous methods and exhibits lower average error, even when considering only signals that meet prior methods’ assumptions. Finally, CAN-D is implemented in lightweight hardware, allowing for an on-board diagnostic (OBD-II) plugin for real-time in-vehicle CAN decoding.

42 ENGINEERING↗

Development and Engineering Design in Support of "Rover Ranch": A K-12 Outreach Software Project

A continuation of the initial development started in the summer of 1999, the body of work performed in support of 'ROVer Ranch' Project during the present fellowship dealt with the concrete concept implementation and resolution of the related issues. The original work performed last summer focused on the initial examination and articulation of the concept treatment strategy, audience and market analysis for the learning technologies software. The presented work focused on finalizing the set of parts to be made available for building an AERCam Sprint type robot and on defining, testing and implementing process necessary to convert the design engineering files to VRML files. Through reverse engineering, an initial set of mission critical systems was designed for beta testing in schools. The files were created in ProEngineer, exported to VRML 1.0 and converted to VRML 97 (VRML 2.0) for final integration in the software. Attributes for each part were assigned using an in-house developed JAVA based program. The final set of attributes for each system, their mutual interaction and the identification of the relevant ones to be tracked, still remain to be decided.

Pascali, Raresh↗

Structure and Interactions of HIV-1 gp41 CHR-NHR Reverse Hairpin Constructs Reveal Molecular Determinants of Antiviral Activity

Engineered reverse hairpin constructs containing a partial C-heptad repeat (CHR) sequence followed by a short loop and full-length N-heptad repeat (NHR) were previously shown to form trimers in solution and to be nanomolar inhibitors of HIV-1 Env mediated fusion. Their target is the in situ gp41 fusion intermediate, and they have similar potency to other previously reported NHR trimers. However, their design implies that the NHR is partially covered by CHR, which would be expected to limit potency. An exposed hydrophobic pocket in the folded structure may be sufficient to confer the observed potency, or they may exist in a partially unfolded state exposing full length NHR. Here, in this study, we examined their structure by crystallography, CD and fluorescence, establishing that the proteins are folded hairpins both in crystal form and in solution. We examined unfolding in the milieu of the fusion reaction by conducting experiments in the presence of a membrane mimetic solvent and by engineering a disulfide bond into the structure to prevent partial unfolding. We further examined the role of the hydrophobic pocket, using a hairpin-small molecule adduct that occluded the pocket, as confirmed by X-ray footprinting. The results demonstrated that the NHR region nominally covered by CHR in the engineered constructs and the hydrophobic pocket region that is exposed by design were both essential for nanomolar potency and that interaction with membrane is likely to play a role in promoting the required inhibitor structure. The design concepts can be applied to other Class 1 viral fusion proteins.

59 BASIC BIOLOGICAL SCIENCES↗

Engineering and evolution of Yarrowia lipolytica for producing lipids from lignocellulosic hydrolysates

Yarrowia lipolytica, an oleaginous yeast, shows promise for industrial fermentation due to its robust acetyl-CoA flux and well-developed genetic engineering tools. However, its lack of an active xylose metabolism restricts the conversion of cellulosic sugars to valuable products. To address this, metabolic engineering, and adaptive laboratory evolution (ALE) were applied to the Y. lipolytica PO1f strain, resulting in an efficient xylose-assimilating strain (XEV). Whole-genome sequencing (WGS) of the XEV followed by reverse engineering revealed that the amplification of the heterologous oxidoreductase pathway and a mutation in the GTPase-activating protein gene (YALI0B12100g) might be the primary reasons for improved xylose assimilation in the XEV strain. When a sorghum hydrolysate was used, the XEV strain showed superior xylose consumption and lipid production compared to its parental strain (X123). This study advances our understanding of xylose metabolism in Y. lipolytica and proposes effective metabolic engineering strategies for optimizing lignocellulosic hydrolysates.

60 APPLIED LIFE SCIENCES↗

RanCompute: Computational Security in Embedded Devices via Random Input and Output Encodings

An embedded device in an insecure environment is subject to additional security risk through capture and reverse-engineering by a capable adversary. If this device contains a microchip performing sensitive computations, capture of the chip may leak functionality to an adversary. In this paper we propose a novel method in which we randomly encode the input operands and the outputs of a computation, thus not revealing the arithmetic operations being performed. The operations are sequenced in a graph representing the overall application. Once the initialization values are overwritten and lost, the results of these computations are indecipherable by the device performing the calculations as well as by any adversary. The result is transmitted back to a secure server which has stored the initialization values and so can decode the results which appear random to the adversary.

Embedded computing↗

Solution of the Navier-Stokes equations for flow within a 2-D thrust reversing nozzle

Implicit numerical procedures have been developed to solve the Reynold's Averaged Navier-Stokes equations for the flowfield within a two-dimensional thrust reversing engine nozzle. The procedures have been tested on four different thrust reverser nozzle geometries with both fixed and moving walls. The results have compared well with available experimental data.

Maccormack, R. W.↗

Analysis of the flow field generated near an aircraft engine operating in reverse thrust

A computer solution is developed to the exhaust gas reingestion problem for aircraft operating in the reverse thrust mode on a crosswind-free runway. The computer program determines the location of the inlet flow pattern, whether the exhaust efflux lies within the inlet flow pattern or not, and if so, the approximate time before the reversed flow reaches the engine inlet. The program is written so that the user is free to select discrete runway speeds or to study the entire aircraft deceleration process for both the far field and cross-ingestion problems. While developed with STOL applications in mind, the solution is equally applicable to conventional designs. The inlet and reversed jet flow fields involved in the problem are assumed to be noninteracting. The nacelle model used in determining the inlet flow field is generated using an iterative solution to the Neuman problem from potential flow theory while the reversed jet flow field is adapted using an empirical correlation from the literature. Sample results obtained using the program are included.

Ledwith, W. A., Jr.↗

Myths and realities: Defining re-engineering for a large organization

This paper describes the background and results of three studies concerning software reverse engineering, re-engineering, and reuse (R3) hosted by the Internal Revenue Service in 1991 and 1992. The situation at the Internal Revenue--aging, piecemeal computer systems and outdated technology maintained by a large staff--is familiar to many institutions, especially among management information systems. The IRS is distinctive for the sheer magnitude and diversity of its problems; the country's tax records are processed using assembly language and COBOL and spread across tape and network DBMS files. How do we proceed with replacing legacy systems? The three software re-engineering studies looked at methods, CASE tool support, and performed a prototype project using re-engineering methods and tools. During the course of these projects, we discovered critical issues broader than the mechanical definitions of methods and tool technology.

Yin, Sandra↗

A Comparative Study of Direct and Indirect Additive Manufacturing Approaches for the Production of a Wind Energy Component

Additive manufacturing (AM) was developed in the 1980s to create three-dimensional prototypes through layer-wise approaches to fabrication. Since then, these approaches have seen improvements in both materials and processing technologies. To date, there are now 7 types of additive manufacturing processes and hundreds of materials, which can be directly printed – going directly from digital design to fabricated components. In this project, Oak Ridge National Laboratory (ORNL), Vestas Wind Systems, and The National Renewable Energy Laboratory (NREL) collaborated to evaluate the effectiveness of state-of-the-art large-scale AM processes in the production of a structural component for use in a wind turbine nacelle, through both direct and indirect manufacturing approaches. Here, experienced AM design engineers detail techniques for AM design, including topology optimization (TO), support minimization, reverse engineering, and techniques for mitigating poor interlaminar performance. Fabrication of the components is presented, including printing parameters and postprocessing, and followed with full-scale component testing by a 3rd party testing laboratory. To evaluate the potential of the developed approaches, a complete techno-economic analysis is provided which evaluates the cost of these techniques given current and near to long-term projections of AM system capabilities.

17 WIND ENERGY↗

High Pressure Reverse Flow APS Engine

A design and test demonstration effort was undertaken to evaluate the concept of the reverse flow engine for the APS engine application. The 1500 lb (6672 N) thrust engine was designed to operate on gaseous hydrogen and gaseous oxygen propellants at a mixture ratio of 4 and to achieve the objective performance of 435 sec (4266 Nsec/kg) specific impulse. Superimposed durability requirements called for a million-cycle capability with 50 hours duration. The program was undertaken as a series of tasks including the initial preliminary design, design of critical test components and finally, the design and demonstration of an altitude engine which could be used interchangeably to examine operating parameters as well as to demonstrate the capability of the concept. The program results are reported with data to indicate that all of the program objectives were met or exceeded within the course of testing on the program. The analysis effort undertaken is also reported in detail and supplemented with test data in some cases where prior definitions could not be made. The results are contained of these analyses as well as the test results conducted throughout the course of the program. Finally, the test data and analytical results were combined to allow recommendations for a flight weight design. This preliminary design effort is also detailed.

Senneff, J. M.↗